Major Cybersecurity Incidents of 2026 Expose Systemic Risks

Cybersecurity incidents reported in 2026 have affected public infrastructure, identity data, healthcare providers, software supply chains and large enterprises. The cases include alleged exposure of Social Security data, attacks on more than 100 US water providers, a breach at IDScan involving more than 150 million driver’s licences, and theft of health data affecting millions of patients.
The breadth of the incidents shows how a compromise can move beyond the initially targeted organisation. Stolen credentials, poorly controlled access, extortion and destructive activity have all contributed to outages, theft of sensitive information and disruption to essential services.
Infrastructure and government systems face sustained pressure
European energy and water systems were among the civilian targets affected by cyberattacks. Poland’s energy grid, a Swedish thermal plant and a Norwegian dam were targeted, while Polish water treatment plants were also attacked. In the United States, CISA said Iranian hackers targeted more than 100 water providers during the summer, including privately owned utilities that may lack basic cybersecurity funding and protections.
US federal agencies also reported major incidents. The FBI disclosed in April that a compromised surveillance system may have exposed phone numbers associated with surveillance targets. In August, the Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a separate major incident involving a system containing targets of ATF investigations.
Identity and health data remain high-value targets
Questions continue over an alleged upload of a live Social Security database to an unsecured third-party server after the Department of Government Efficiency entered the Social Security Administration. A federal whistleblower alleged that the database included Social Security numbers and related personal information for most living Americans. Court filings indicated that the agency was uncertain about what was held on the server.
IDScan confirmed a breach after attackers advertised a dark-web search service containing images of 150 million drivers in the United States and Canada. The incident followed other exposures involving passports and driving licences held by hotel, money-transfer, prison payphone and visa services. Such records can create lasting risks because identity documents are increasingly required for access and verification.
Healthcare organisations were also heavily affected. DentaQuest reported the theft of health data relating to 15 million people, while CareCloud said a breach affected at least 3.7 million people. Aesto Health later confirmed that an incident discovered late in the prior year affected at least 9.5 million patients across providers and practices using its software.
Credential failures and supplier compromises widen impact
Klue said an extortion group accessed its systems using a credential issued in 2022 for a limited pilot. The breach affected close to 200 customers, including Jamf, HackerOne and LastPass, and exposed keys to customers’ cloud services. Klue told customers it had reached an agreement intended to prevent publication of stolen data, but another group was said to hold some customer data.
Supply-chain compromises also affected Aqua Security’s Trivy, Bitwarden, Checkmarx and other open-source projects. Backdoored software and stolen credentials enabled attackers to take passwords, credentials and tokens from affected systems, with downstream exposure reaching organisations including OpenAI and Vercel. The EU’s cyber agency later confirmed a major data theft involving stolen cloud keys.
For businesses, the practical implication is clear: inventory and retire legacy credentials, restrict third-party and cloud access, protect software update paths, and rehearse incident recovery. These measures will not eliminate attacks, but they can reduce the chance that one compromised account becomes a prolonged operational and data-security crisis.

